TrueML Logo

TrueML

Sr. Application Security Engineer

Posted An Hour Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
125K-140K Annually
Senior level
Remote
Hiring Remotely in United States
125K-140K Annually
Senior level
Lead application security across the SDLC: integrate security into development and DevOps, manage vulnerabilities, implement AWS and cloud controls, perform threat modeling and incident response, enforce compliance (OWASP, NIST, ISO), and provide security training and continuous improvement.
The summary above was generated by AI
Why TrueML?

TrueML is a mission-driven financial software company that aims to create better customer experiences for distressed borrowers. Consumers today want personal, digital-first experiences that align with their lifestyles, especially when it comes to managing finances. TrueML’s approach uses machine learning to engage each customer digitally and adjust strategies in real time in response to their interactions. 

The TrueML team includes inspired data scientists, financial services industry experts and customer experience fanatics building technology to serve people in a way that recognizes their unique needs and preferences as human beings and endeavoring toward ensuring nobody gets locked out of the financial system.

The Opportunity

    We are seeking a talented and motivated Senior Application Security Engineer with a strong background in AWS and DevOps practices. In this role, you will be responsible for ensuringthe security of our applications throughout the development lifecycle. You will work closelywith engineering teams to identify and mitigate security vulnerabilities, implement securitybest practices, and contribute to the organization's overall security strategy. The ideal candidate will have excellent communication skills and the ability to collaborate effectively with cross-functional teams.

What You'll Do:

  • Security Integration: Work with development and DevOps teams to integrate security into the software development lifecycle (SDLC).

  • Vulnerability Management: Identify, assess, and mitigate security vulnerabilities in applications, infrastructure, and cloud environments.

  • AWS Security: Implement and maintain security controls in AWS, including IAM policies, security groups, VPC configurations, and monitoring.

  • DevOps Security: Collaborate with DevOps teams to incorporate security best practices in CI/CD pipelines, including automated testing, secure code reviews, and infrastructure as code (IaC) security.

  • Threat Modeling: Conduct threat modeling and risk assessments to identify potential security threats and develop mitigation strategies.

  • Incident Response: Assist in developing and executing incident response plans, including identifying and responding to security incidents.

  • Compliance & Best Practices: Ensure that all systems and applications comply with relevant security standards, regulations, and best practices (e.g., OWASP , NIST , ISO 27001).• Security Training: Provide security training and guidance to engineering teams to promote secure coding and infrastructure management practices.

  • Continuous Improvement: Continuously monitor, evaluate, and improve security practices, tools, and processes.

Who You Are:

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.

  • 8+ years of experience in application security or a related role.

  • Strong experience with AWS security services and best practices.

  • Experience with DevOps tools and practices, including CI/CD pipelines, containerization, and IaC.

  • Proficiency in at least one programming language (e.g., Python, Go).

  • Strong understanding of web application security (e.g., OWASP Top Ten) and secure coding practices.

  • Familiarity with security tools and technologies such as SAST , DAST , SIEM, and WAFs.

  • Ability to work well in a team environment and collaborate effectively with engineers, developers, and other stakeholders.

  • AWS Certified Security – Specialty or similar certification.

  • Experience with container security (e.g., Docker, Kubernetes).

  • Familiarity with modern authentication and authorization protocols (e.g., OAuth, SAML, JWT). Knowledge of secure coding frameworks and libraries.

What We Offer (Perks & Benefits)

  • Flexible vacation

  • Medical/dental/vision insurance

  • Traditional/Roth retirement savings options

  • Company-paid disability and life insurance

  • Flexible Spending Account & Limited FSA

  • Family-friendly parental leave, volunteer and voting time off

  • On-demand wellness platform access for you and 5 friends and family

  • PerkSpot discount program for 900+ merchants nationwide

Remote Work, Travel Expectations & Physical Requirements:

This role supports a global, cross-functional business and operates primarily in a Remote-First environment. However, flexibility outside of standard business hours and occasional local or international travel may be necessary for global operations support, company meetings, training, offsites, and collaborative projects.

This position primarily involves computer-based work, requiring extended periods at a computer, participation in virtual meetings, and use of standard office technology. We will consider reasonable accommodations to enable individuals to perform the essential functions of the role.

Maintaining a reliable internet connection and a professional work environment is expected. The ability to protect confidential company, employee, customer, and business information while working outside of a company office is also required.

Personally Identifying Information

We collect personal information for employment purposes. We do not sell personal information. Most of the information we have is provided to us by you and/or collected as part of the employment process. For more details on how we use, share, and delete personal information see our Privacy Policy.

 

Dedication to Diversity & Inclusion

We are  an equal opportunity employer. We promote, value, and thrive with a diverse and inclusive team. Different perspectives contribute to better solutions and this makes us stronger every day. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.

TrueML San Francisco, California, USA Office

San Francisco, CA, United States, 94105

Similar Jobs at TrueML

An Hour Ago
Remote
United States
115K-140K Annually
Senior level
115K-140K Annually
Senior level
Fintech • Machine Learning • Payments • Social Impact • Software • Financial Services
Lead and develop a Platform Enablement team that bridges client-facing organizations and Engineering. Oversee escalation governance, triage efficiency, documentation strategy, telemetry-driven advocacy, process automation, and GenAI adoption to reduce MTTR and systemic platform friction. Serve as cross-functional translator for stakeholders and drive data-backed improvements to product and infrastructure.
Top Skills: Browser DevtoolsCi/CdClaudeConfluenceCurlDatadogGeminiGithub CopilotInfrastructure-As-CodeJSONObservePostmanSQL
Yesterday
In-Office or Remote
San Francisco, CA, USA
170K-220K Annually
Senior level
170K-220K Annually
Senior level
Fintech • Machine Learning • Payments • Social Impact • Software • Financial Services
Lead infrastructure and platform engineering for cloud architecture, CI/CD standards, and scalability of machine learning products, while managing a team of DevOps engineers.
Top Skills: ArgocdAtlantisAWSBashDatadogGithub ActionsGoKubernetesObservePythonTerraform
7 Days Ago
Remote
United States
120K-155K Annually
Senior level
120K-155K Annually
Senior level
Fintech • Machine Learning • Payments • Social Impact • Software • Financial Services
The Payment Operations Manager will lead the strategy for payment transactions, optimize workflows, manage relationships with payment providers, and ensure compliance with regulatory standards.
Top Skills: AchCredit/Debit CardsDigital WalletsPayment GatewaysRtpSepaSQL

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account